Cybersecurity Services

Expose What Attackers
Find First.

VSAT Security offers external penetration testing and standalone vulnerability scans — including compliance scans that satisfy cyber insurance requirements. We scope every engagement to your exact needs.

Our Services

Two Ways We Help

Whether you need a full adversarial simulation or a compliance scan for your cyber insurer, we have you covered.

External Penetration Testing

Full adversarial simulation

A full external penetration test simulates a motivated attacker targeting your organisation from the internet — no insider knowledge, no internal network access. Our testers use the same tools and techniques as real threat actors: OSINT-driven credential gathering, credential stuffing and spraying, and systematic attack surface enumeration.

We stop at the point of access, document exactly how we got in, and deliver a full written report with remediation steps and CVSS scores.

  • Zero insider knowledge — black-box methodology
  • OSINT-driven reconnaissance of public data
  • Credential gathering from breached data sources
  • Credential stuffing & account takeover attempts
  • Attack surface inventory with risk ratings
  • Full written report + executive summary + debrief

Vulnerability Scanning

Standalone — cyber insurance compliant

Not every organisation needs a full penetration test. Many cyber insurers only require a vulnerability scan as proof of regular security assessment — and a full pentest is often overkill for that requirement.

VSAT offers standalone vulnerability scans as a separate, cost-effective service. We scan your external-facing infrastructure for known CVEs and misconfigurations, and provide a formal report you can submit directly to your cyber insurer.

  • Automated + validated scan of external infrastructure
  • CVE identification with CVSS severity ratings
  • Misconfiguration and exposure detection
  • Formal written report accepted by major cyber insurers
  • Faster turnaround than a full engagement
  • Ideal for annual compliance cycles

VSAT now carries active Cyber Liability insurance. Our vulnerability scanning service is backed by real, compliance-aligned coverage — a credibility signal your cyber insurer can rely on, not a future intent.

Pentest Capabilities

What We Target

The following capabilities apply to our full external penetration testing service.

Credential Attacks

Password spraying, brute-force, credential stuffing against externally exposed login portals — Active Directory, SSO, email services, and SaaS platforms.

Credential Harvesting & Stuffing

OSINT-driven collection of leaked and exposed credentials, followed by systematic credential stuffing and password spraying against your externally accessible accounts and services.

External Attack Surface Mapping

Enumerate your public-facing infrastructure — subdomains, open ports, exposed APIs, and misconfigured services — to understand exactly what attackers can see.

Scope

What's In —
And What's Not

We operate strictly within the agreed external perimeter. We do not pivot from an external compromise into your internal network. Our focus is on the attack surface visible from the internet — this keeps the engagement scoped, safe, and highly relevant to real-world external threats.

Internet-facing login portals
Email account takeover attempts
Credential gathering & stuffing attacks
External subdomain enumeration
VPN / Remote Access gateway testing
Pivoting to internal network segmentsOut of scope
Internal host lateral movementOut of scope
Active Directory domain compromiseOut of scope

Why It Matters

The Cost of Not Testing

External attack vectors are the primary entry point for modern breaches. Without regular testing, these risks remain invisible until it's too late.

Business Email Compromise

Attackers take over a single mailbox and impersonate executives to redirect wire transfers — average loss exceeds $130,000 per incident.

Ransomware Entry Points

83% of ransomware intrusions begin with a compromised external credential or exploited vulnerability. External testing closes that door before attackers open it.

Compliance Exposure

SOC 2, ISO 27001, and PCI-DSS all require evidence of regular penetration testing. A breach without documented tests means failed audits and regulatory fines.

Reputational Damage

Customer data breaches are public. The cost of a breach averages $4.45M, but the reputational hit often outlasts the recovery bill.

The average time to identify a breach is 194 days. By then, attackers have had over six months of undetected access to your systems, email, and customer data. External pen testing finds the door before they walk through it.

Our Process

From Kickoff to Report

01

Scoping Call

We define the target domains, IPs, and systems. Rules of engagement are documented and signed off before any testing begins.

02

Reconnaissance

Passive and active OSINT against your organisation — leaked credentials, exposed endpoints, email format discovery, and shadow IT inventory.

03

Attack Execution

Controlled execution of credential attacks, external vulnerability exploitation, and systematic attack surface testing against agreed targets.

04

Reporting & Debrief

Detailed written report with findings, CVSS scores, screenshots, and remediation steps. Live debrief call with your security team included.

Get Pricing

Request
Pricing.

Tell us what you need — full pentest or a standalone vulnerability scan for cyber insurance — and we'll reach out with a scoped proposal tailored to your environment.

External pentest or vulnerability scan — we scope it
Cyber insurance compliance reports available
Fixed-price, transparent engagements
NDA available before scoping call

Let's Talk Security

Reach out to the VSAT Security team directly and we'll get back to you within 24 business hours. Tell us about your environment and the engagement you have in mind.

Your email client will open with the subject and a short prompt — just add your company name and the services you're interested in, then hit send.